diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml index 96dfe3a..052ff3f 100644 --- a/.github/workflows/codeql.yaml +++ b/.github/workflows/codeql.yaml @@ -19,7 +19,7 @@ jobs: actions: read contents: read security-events: write - uses: thingzio/actions/.github/workflows/codeql-go.yaml@368b3e12df4c41d9079b26e41a03efcd90461d56 # v1.7.1 + uses: thingzio/actions/.github/workflows/codeql-go.yaml@7276775800dbfef1d9671e60c337f3b4b479a4e8 # v1.8.0 with: # .go-version owns the toolchain here, not .versions.yaml, so that # setup-go can read it without a YAML parser. diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 21601b5..d09c5e1 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -157,7 +157,7 @@ jobs: # receives it, and that job runs no code from this repository. id-token: write attestations: write - uses: thingzio/actions/.github/workflows/release-go.yaml@368b3e12df4c41d9079b26e41a03efcd90461d56 # v1.7.1 + uses: thingzio/actions/.github/workflows/release-go.yaml@7276775800dbfef1d9671e60c337f3b4b479a4e8 # v1.8.0 with: # Passed explicitly, not inherited. v1.7.0 changed this input's default # from .go-version to go.mod; both say 1.27.1 here so the result is the